Skip to content
KitploitKITPLOIT
उपकरणब्लॉग
जमा करें
उपकरणब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
zeek-quasarrat-detector — Zeek detector for QuasarRat | Kitploit
उपकरण/GitHubGitHub/corelight/zeek-quasarrat-detector
Network SecurityMalware AnalysisThreat IntelligenceIntrusion DetectionAnomaly Detection
GitHubcorelight/zeek-quasarrat-detector

zeek-quasarrat-detector

Zeek detector for QuasarRat

रिपॉजिटरी देखें
3110 महीने पहलेअभी तक समीक्षित नहीं

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें

Zeek-आधारित QuasarRAT मैलवेयर डिटेक्टर

मैलवेयर अक्सर अपने कमांड और कंट्रोल (C2) सर्वर के साथ संचार HTTPS पर छिपाता है। HTTPS में एन्क्रिप्शन आमतौर पर समझौते को इतनी देर तक छिपाए रखता है कि मैलवेयर अपना लक्ष्य पूरा कर ले। यह HTTPS का उपयोग करने वाले मैलवेयर का पता लगाना चुनौतीपूर्ण बनाता है, लेकिन कभी-कभी आपको मौका मिल जाता है, जैसा कि यहाँ QuasarRAT के मामले में है, जो एक Windows रिमोट एक्सेस टूल है जिसे पिछले वर्ष में संयुक्त राज्य में महत्वपूर्ण बुनियादी ढांचे का प्रबंधन करने वाले संगठनों को निशाना बनाने के लिए तैनात किया गया है।

उदाहरण Notice.log आउटपुट

root@kitploit:~
#separator \x09
#set_separator	,
#empty_field	(empty)
#unset_field	-
#path	notice
#open	2024-10-09-18-06-57
#fields	ts	uid	id.orig_h	id.orig_p	id.resp_h	id.resp_p	fuid	file_mime_type	file_desc	proto	note	msg	sub	src	dst	p	n	peer_descr	actions	email_dest	suppress_for	remote_location.country_code	remote_location.region	remote_location.city	remote_location.latitude	remote_location.longitude
#types	time	string	addr	port	addr	port	string	string	string	enum	enum	string	string	addr	addr	port	count	string	set[enum]	set[string]	interval	string	string	string	double	double
1723831638.402474	CpKJJiDUPEBNMGSC	192.168.100.7	49744	86.136.67.231	1337	-	-	-	tcp	QuasarRAT::C2_Traffic_Observed_Cert	Potential QuasarRAT C2 - default SSL certificate discovered.	-	192.168.100.7	86.136.67.231	1337	-	-	Notice::ACTION_LOG	(empty)	3600.000000	-	-	-	-	-
#close	2024-10-09-18-06-57

Suricata नियम

आप "suri" निर्देशिका में Suricata नियम पा सकते हैं।

PCAP स्रोत

  • QuasarRAT
    • https://app.any.run/tasks/09ffabf7-774a-43a3-8c97-68f2046fd385#
    • https://app.any.run/tasks/e381f9d7-5038-42d1-9845-e79be15c036d#
    • https://app.any.run/tasks/09ffabf7-774a-43a3-8c97-68f2046fd385
    • https://app.any.run/tasks/9e1222a6-4ec4-46f0-bf27-ff77db65b645
    • https://app.any.run/tasks/2bcb2f8f-6aab-420e-a847-90f2788beddd
    • https://app.any.run/tasks/36bf4f77-a915-4c15-9f17-93940f4cfb83
टूल डाउनलोड करें